![]() |
Flacor.dat entdeckt hallo leute, ich habe vor ca. 1 Woche festgestellt, dass sich der pc automatisch hunterfährt nach einem kurzen hinweis. Seit dem kam immer eine Fehlermeldung mit der datei flacor.dat. Nach ein wenig googeln wusste ich dann was ich mir da eingefangen hab, daraufhin einen vollständigen scan mit malwarebytes gemacht und die datei flacor.dat entfernt: Code: Malwarebytes' Anti-Malware 1.46 file1 OTL Logfile: Code: OTL logfile created on: 30.07.2010 20:25:23 - Run 1 file 2 OTL Logfile: Code: OTL Extras logfile created on: 30.07.2010 20:25:23 - Run 1 superantisyware hat nichts mehr gefunden, cc-cleaner hab ich auch durchlaufen lassen, passwörter habe ich alle geändert... kann ich jetzt beruigt weitersurfen oder muss ich mir noch sorgen machen??? ich bedanke mich schonmal für die antworten kann erst am montag wieder antworten da ich morgen übers we weg fahre... grüße Arthur |
Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code: :OTL Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. |
hab ich wie beschrieben gemacht, hier das logfile: PHP-Code: |
Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
http://saved.im/mtm0nzyzmzd5/cofi.jpg
Es sollte nie auf eigene Initiative hin ausgeführt werden! Eine falsche Benutzung kann ernsthafte Computerprobleme nach sich ziehen und eine Bereinigung der Infektion noch erschweren. |
hallo, hab combofix nun wie beschrieben ausgeführt hier das file: Combofix Logfile: Code: ComboFix 10-08-02.03 - Arthur 03.08.2010 19:20:28.1.2 - x86 |
Ok. Bitte nun Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus Anschließend den bootkit_remover herunterladen. Entpacke das Tool in einen eigenen Ordner auf dem Desktop und führe in diesem Ordner die Datei remove.exe aus. Wenn Du Windows Vista oder Windows 7 verwendest, musst Du die remover.exe über ein Rechtsklick => als Administrator ausführen Ein schwarzes Fenster wird sich öffnen und automatisch nach bösartigen Veränderungen im MBR suchen. Poste dann bitte, ob es Veränderungen gibt und wenn ja in welchem device. Am besten alles posten was die remover.exe ausgibt. |
hallo, habe die programme wie beschrieben ausgeführt: gmer: GMER Logfile: Code: GMER 1.0.15.15281 - hxxp://www.gmer.net osam: Report of OSAM: Autorun Manager v5.0.11926.0 hxxp://www.online-solutions.ru/en/ Saved at 19:26:05 on 05.08.2010 OS: Windows Vista Home Premium Edition Service Pack 1 (Build 6001), 32-bit Default Browser: Mozilla Corporation Firefox 3.6.8 Scanner Settings Rootkits detection (hidden registry) Rootkits detection (hidden files) Retrieve files information Check Microsoft signatures Filters Trusted entries Empty entries Hidden registry entries (rootkit activity) Exclusively opened files Not found files Files without detailed information Existing files Non-startable services Non-startable drivers Active entries Disabled entries Risk Name Publisher Full Path Status AppInit DLLs HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows |||| "AppInit_DLLs" "Google" C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll File exists Control Panel Objects %SystemRoot%\system32 || "DivXControlPanelApplet.cpl" "DivX, Inc." C:\Windows\system32\DivXControlPanelApplet.cpl File exists |||||| "PhysX.cpl" "NVIDIA Corporation" C:\Windows\system32\PhysX.cpl File exists HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls |||||| "QuickTime" "Apple Inc." C:\Program Files\QuickTime\QTSystem\QuickTime.cpl File exists Drivers HKLM\SYSTEM\CurrentControlSet\Services "a7dnvet2" (a7dnvet2) C:\Windows\system32\drivers\a7dnvet2.sys Hidden registry entry, rootkit activity | File not found |||||| "AlfaFF File System mini-filter" (AlfaFF) "Alfa Corporation" C:\Windows\System32\Drivers\AlfaFF.sys File exists |||||| "at7i08x0" (at7i08x0) "Microsoft Corporation" C:\Windows\system32\drivers\at7i08x0.sys Hidden registry entry, rootkit activity | File signed by Microsoft |||||| "atksgt" (atksgt) C:\Windows\System32\DRIVERS\atksgt.sys File found, but it contains no detailed information |||||| "avgio" (avgio) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\avgio.sys File exists |||||| "avgntflt" (avgntflt) "Avira GmbH" C:\Windows\System32\DRIVERS\avgntflt.sys File exists |||||| "avipbb" (avipbb) "Avira GmbH" C:\Windows\System32\DRIVERS\avipbb.sys File exists "catchme" (catchme) C:\cofi\catchme.sys File not found |||||| "int15" (int15) C:\Windows\system32\drivers\int15.sys File found, but it contains no detailed information "IP in IP Tunnel Driver" (IpInIp) C:\Windows\System32\DRIVERS\ipinip.sys File not found "IPX Traffic Filter Driver" (NwlnkFlt) C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found "IPX Traffic Forwarder Driver" (NwlnkFwd) C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found |||||| "lirsgt" (lirsgt) C:\Windows\System32\DRIVERS\lirsgt.sys File found, but it contains no detailed information |||||| "NTIPPKernel" (NTIPPKernel) "Cyberlink Corp." C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys File exists "ntnzl" (ntnzl) C:\Windows\system32\drivers\ntnzl.sys File not found |||||| "PSDFilter" (PSDFilter) "Egis Incorporated" C:\Windows\System32\DRIVERS\psdfilter.sys File exists |||||| "PSDNServ" (PSDNServ) "Egis Incorporated" C:\Windows\System32\DRIVERS\PSDNServ.sys File exists |||||| "PSDVdisk" (psdvdisk) "Egis Incorporated" C:\Windows\System32\DRIVERS\PSDVdisk.sys File exists |||||| "SASDIFSV" (SASDIFSV) "SUPERAdBlocker.com and SUPERAntiSpyware.com" C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS File exists |||||| "SASKUTIL" (SASKUTIL) "SUPERAdBlocker.com and SUPERAntiSpyware.com" C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS File exists |||||| "sptd" (sptd) "Duplex Secure Ltd." C:\Windows\System32\Drivers\sptd.sys File is exclusively opened, access blocked |||||| "ssmdrv" (ssmdrv) "Avira GmbH" C:\Windows\System32\DRIVERS\ssmdrv.sys File exists |||||| "UBHelper" (UBHelper) "NewTech Infosystems Corporation" C:\Windows\system32\drivers\UBHelper.sys File exists |||||| "Upper Class Filter Driver" (NTIDrvr) "NewTech Infosystems, Inc." C:\Windows\System32\DRIVERS\NTIDrvr.sys File exists "vaxscsi" (vaxscsi) C:\Windows\System32\Drivers\vaxscsi.sys File not found |||||| "WSVD" (WSVD) "CyberLink" C:\Windows\system32\drivers\WSVD.sys File exists |||||| "{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}" ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) "Cyberlink Corp." C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl File exists Explorer HKLM\Software\Classes\Folder\shellex\ColumnHandlers |||||| {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" "Adobe Systems, Inc." C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll File exists |||||| {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists HKLM\Software\Classes\Protocols\Filter |||| {B1759355-3EEC-4C1E-B0F1-B719FE26E377} "Google Dictionary Compression filter" "Google Inc." C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll File exists HKLM\Software\Classes\Protocols\Handler |||| {828030A1-22C1-4009-854F-8E305202313F} "livecall" "Microsoft Corporation" C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL File exists |||||| {0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" "Microsoft Corporation" c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll File exists |||| {828030A1-22C1-4009-854F-8E305202313F} "msnim" "Microsoft Corporation" C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL File exists |||||| {03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" "Microsoft Corporation" C:\Program Files\Windows Live\Mail\mailcomm.dll File exists HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" File not found | COM-object registry key not found HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved {911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" File not found | COM-object registry key not found {1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" File not found | COM-object registry key not found {34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" File not found | COM-object registry key not found |||||| {0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter" "Microsoft Corporation" C:\Program Files\Windows Live\Mail\mailcomm.dll File exists {0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" File not found | COM-object registry key not found |||||| {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} "DragDropProtect Class" "Egis Inc." C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll File exists {2b45bd21-71f8-4c8c-a87a-7eeb25a1a3e0} "EPM-PO Shell Extensions" epm-po.dll File not found {2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" File not found | COM-object registry key not found |||||| {8F9D8FBE-C5C1-4B65-986E-51235C9283E8} "FPLaunchCache" "Arachnoid Biometrics Identification Group Corp." C:\Program Files\Acer\Acer Bio Protection\FPLaunchCache.dll File exists |||||| {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" "Apple Inc." C:\Program Files\iTunes\iTunesMiniPlayer.dll File exists {00020d75-0000-0000-c000-000000000046} "lnkfile" File not found | COM-object registry key not found |||||| {FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} "Meine freigegebenen Ordner" "Microsoft Corporation" C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll File exists |||||| {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists |||||| {087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists |||||| {63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists |||||| {3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists {C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" File not found | COM-object registry key not found {E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" File not found | COM-object registry key not found |||||| {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\shlext.dll File exists {1C311AAA-D8B1-4A0A-BEE5-2387FEC583DA} "ShellPlusContextMenu" File not found | COM-object registry key not found {da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" File not found | COM-object registry key not found |||||| {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" C:\Program Files\WinRAR\rarext.dll File found, but it contains no detailed information Internet Explorer HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser |||| "Google Toolbar" "Google Inc." C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll File exists "ITBar7Layout" File not found | COM-object registry key not found |||| "Toolbar fuer eBay" C:\Users\Arthur\AppData\Roaming\Toolbars\Toolbar fuer eBay\ebay.dll File exists |||| "Winamp Toolbar" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks |||| {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} "Winamp Search Class" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists || {40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" "Conduit Ltd." C:\Program Files\Winload\tbWinl.dll File exists HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units |||| {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_20" hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2iexp.dll File exists |||| {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2iexp.dll File exists |||| {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\npjpi160_20.dll File exists HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions |||||| "Quick-Launching Area" C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe File exists HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar |||||| "Acer eDataSecurity Management" "Egis Incorporated." C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll File exists |||| "Google Toolbar" "Google Inc." C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll File exists |||| "Toolbar fuer eBay" C:\Users\Arthur\AppData\Roaming\Toolbars\Toolbar fuer eBay\ebay.dll File exists |||| {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} "Winamp Toolbar" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists || {40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" "Conduit Ltd." C:\Program Files\Winload\tbWinl.dll File exists HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects |||||| {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader Link Helper" "Adobe Systems Incorporated" C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll File exists |||| {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} "Google Dictionary Compression sdch" "Google Inc." C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll File exists |||| {AA58ED58-01DD-4d91-8333-CF10577473F7} "Google Toolbar Helper" "Google Inc." C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll File exists |||| {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" "Google Inc." C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll File exists |||| {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2ssv.dll File exists |||||| {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} "ShowBarObj Class" "Egis" C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll File exists |||| {AA61DE26-FA67-4575-9033-918671094293} "TBSB03968 Class" C:\Users\Arthur\AppData\Roaming\Toolbars\Toolbar fuer eBay\ebay.dll File exists |||| {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} "Winamp Toolbar Loader" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists || {40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" "Conduit Ltd." C:\Program Files\Winload\tbWinl.dll File exists {02478D38-C3F9-4efb-9B51-7695ECA05670} "{02478D38-C3F9-4efb-9B51-7695ECA05670}" File not found | COM-object registry key not found {7E853D72-626A-48EC-A868-BA8D5E23E045} "{7E853D72-626A-48EC-A868-BA8D5E23E045}" File not found | COM-object registry key not found Logon %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup |||||| "desktop.ini" C:\Users\Arthur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini File exists %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup |||||| "desktop.ini" C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini File exists HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |||| "AlcoholAutomount" "Alcohol Soft Development Team" "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount File exists |||| "Orb" "Orb Networks" "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background File exists |||||| "SUPERAntiSpyware" "SUPERAntiSpyware.com" C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe File exists |||| "swg" "Google Inc." "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" File exists HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd "StartupPrograms" rdpclip File not found HKLM\Software\Microsoft\Windows\CurrentVersion\Run |||| "Adobe Reader Speed Launcher" "Adobe Systems Incorporated" "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" File exists |||| "ArcadeDeluxeAgent" "CyberLink Corp." "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" File exists |||||| "avgnt" "Avira GmbH" "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min File exists |||||| "BkupTray" "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" File exists |||| "CLMLServer" "CyberLink" "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" File exists |||| "DAEMON Tools" "DT Soft Ltd." "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 File exists || "DivXUpdate" "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW File exists |||| "eAudio" "Acer Incorporated" "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe" File exists |||||| "eDataSecurity Loader" "Egis Incorporated" C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe File exists |||||| "ePower_DMC" "Acer Inc." C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe File exists |||| "Google Desktop Search" "Google" "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup File exists |||| "HostManager" "America Online, Inc." C:\Program Files\Common Files\AOL\1223197373\ee\AOLSoftware.exe File exists |||| "IAAnotif" "Intel Corporation" C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe File exists |||| "iTunesHelper" "Apple Inc." "C:\Program Files\iTunes\iTunesHelper.exe" File exists |||| "LexwareInfoService" "Lexware GmbH & Co. KG" C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe /autostart File exists |||| "LManager" "Dritek System Inc." C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE File exists |||||| "Malwarebytes Anti-Malware (reboot)" "Malwarebytes Corporation" "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript File exists |||| "PlayMovie" "Acer Corp." "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" File exists || "PLFSetI" C:\Windows\PLFSetI.exe File exists |||| "QuickTime Task" "Apple Inc." "C:\Program Files\QuickTime\QTTask.exe" -atboottime File exists |||| "SunJavaUpdateSched" "Sun Microsystems, Inc." "C:\Program Files\Common Files\Java\Java Update\jusched.exe" File exists |||| "WarReg_PopUp" "Acer Incorporated" C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe File exists |||| "WinampAgent" "C:\Program Files\Winamp\winampa.exe" File found, but it contains no detailed information |||| "ZPdtWzdVitaKey MC3000" "Arachnoid Biometrics Identification Group Corp." "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show File exists Print Monitors HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors |||||| "PDFCreator" C:\Windows\system32\pdfcmnnt.dll File found, but it contains no detailed information Services HKLM\SYSTEM\CurrentControlSet\Services |||||| "AOL Connectivity Service" (AOL ACS) "AOL LLC" C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe File exists |||||| "Apple Mobile Device" (Apple Mobile Device) "Apple Inc." C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe File exists |||||| "Avira AntiVir Guard" (AntiVirService) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\avguard.exe File exists |||||| "Avira AntiVir Planer" (AntiVirSchedulerService) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\sched.exe File exists |||||| "CLHNService" (CLHNService) C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe File exists |||||| "Cyberlink RichVideo Service(CRVS)" (RichVideo) C:\Program Files\Cyberlink\Shared files\RichVideo.exe File exists |||||| "Dienst "Bonjour"" (Bonjour Service) "Apple Inc." C:\Program Files\Bonjour\mDNSResponder.exe File exists |||||| "eDataSecurity Service" (eDataSecurity Service) "Egis Incorporated" C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe File exists |||||| "Empowering Technology Service" (ETService) C:\Program Files\Acer\Empowering Technology\Service\ETService.exe File exists |||||| "FLEXnet Licensing Service" (FLEXnet Licensing Service) "Macrovision Europe Ltd." C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe File exists |||| "Google Desktop Manager 5.9.911.3589" (GoogleDesktopManager-110309-193829) "Google" C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe File exists |||| "Google Software Updater" (gusvc) "Google" C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe File exists |||||| "iGroupTec Service" (IGBASVC) C:\Program Files\Acer\Acer Bio Protection\BASVC.exe File found, but it contains no detailed information |||| "InstallDriver Table Manager" (IDriverT) "Macrovision Corporation" C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe File exists |||||| "Intel(R) Matrix Storage Event Monitor" (IAANTMON) "Intel Corporation" C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe File exists |||||| "iPod-Dienst" (iPod Service) "Apple Inc." C:\Program Files\iPod\bin\iPodService.exe File exists |||||| "LightScribeService Direct Disc Labeling Service" (LightScribeService) "Hewlett-Packard Company" C:\Program Files\Common Files\LightScribe\LSSrvc.exe File exists |||||| "MobilityService" (MobilityService) C:\Acer\Mobility Center\MobilityService.exe File exists |||||| "NMSAccessU" (NMSAccessU) C:\Program Files\CDBurnerXP\NMSAccessU.exe File found, but it contains no detailed information |||||| "NTI Backup Now 5 Agent Service" (BUNAgentSvc) "NewTech Infosystems, Inc." C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe File exists |||||| "NTI Backup Now 5 Backup Service" (NTIBackupSvc) "NewTech InfoSystems, Inc." C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe File exists |||||| "NTI Backup Now 5 Scheduler Service" (NTISchedulerSvc) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe File found, but it contains no detailed information |||||| "Raw Socket Service" (RS_Service) "Acer Incorporated" C:\Program Files\Acer\Acer VCM\RS_Service.exe File exists || "Sony Ericsson OMSI download service" (OMSI download service) C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe File found, but it contains no detailed information |||||| "StarWind AE Service" (StarWindServiceAE) "Rocket Division Software" C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe File exists Winlogon HKCU\Control Panel\Desktop "SCRNSAVE.EXE" C:\Windows\System32\acer.scr File found, but it contains no detailed information HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify |||||| "AWinNotifyVitaKey MC3000" "Arachnoid Biometrics Identification Group Corp." C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll File exists |||||| "spba" "UPEK Inc." C:\Program Files\Common Files\SPBA\homefus2.dll File exists Winsock Providers HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries |||||| "mdnsNSP" "Apple Inc." C:\Program Files\Bonjour\mdnsNSP.dll File exists If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru und HTML-Code: <c> 2009 e Sage Lab |
Zitat:
Downloade Dir danach bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
|
löschen erledigt... OSAM: Report of OSAM: Autorun Manager v5.0.11926.0 hxxp://www.online-solutions.ru/en/ Saved at 20:07:22 on 05.08.2010 OS: Windows Vista Home Premium Edition Service Pack 1 (Build 6001), 32-bit Default Browser: Mozilla Corporation Firefox 3.6.8 Scanner Settings Rootkits detection (hidden registry) Rootkits detection (hidden files) Retrieve files information Check Microsoft signatures Filters Trusted entries Empty entries Hidden registry entries (rootkit activity) Exclusively opened files Not found files Files without detailed information Existing files Non-startable services Non-startable drivers Active entries Disabled entries Risk Name Publisher Full Path Status AppInit DLLs HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows |||| "AppInit_DLLs" "Google" C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll File exists Control Panel Objects %SystemRoot%\system32 || "DivXControlPanelApplet.cpl" "DivX, Inc." C:\Windows\system32\DivXControlPanelApplet.cpl File exists |||||| "PhysX.cpl" "NVIDIA Corporation" C:\Windows\system32\PhysX.cpl File exists HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls |||||| "QuickTime" "Apple Inc." C:\Program Files\QuickTime\QTSystem\QuickTime.cpl File exists Drivers HKLM\SYSTEM\CurrentControlSet\Services "a7dnvet2" (a7dnvet2) C:\Windows\system32\drivers\a7dnvet2.sys Hidden registry entry, rootkit activity | File not found |||||| "AlfaFF File System mini-filter" (AlfaFF) "Alfa Corporation" C:\Windows\System32\Drivers\AlfaFF.sys File exists |||||| "at7i08x0" (at7i08x0) "Microsoft Corporation" C:\Windows\system32\drivers\at7i08x0.sys Hidden registry entry, rootkit activity | File signed by Microsoft |||||| "atksgt" (atksgt) C:\Windows\System32\DRIVERS\atksgt.sys File found, but it contains no detailed information |||||| "avgio" (avgio) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\avgio.sys File exists |||||| "avgntflt" (avgntflt) "Avira GmbH" C:\Windows\System32\DRIVERS\avgntflt.sys File exists |||||| "avipbb" (avipbb) "Avira GmbH" C:\Windows\System32\DRIVERS\avipbb.sys File exists "catchme" (catchme) C:\cofi\catchme.sys File not found |||||| "int15" (int15) C:\Windows\system32\drivers\int15.sys File found, but it contains no detailed information "IP in IP Tunnel Driver" (IpInIp) C:\Windows\System32\DRIVERS\ipinip.sys File not found "IPX Traffic Filter Driver" (NwlnkFlt) C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found "IPX Traffic Forwarder Driver" (NwlnkFwd) C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found |||||| "lirsgt" (lirsgt) C:\Windows\System32\DRIVERS\lirsgt.sys File found, but it contains no detailed information |||||| "NTIPPKernel" (NTIPPKernel) "Cyberlink Corp." C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys File exists |||||| "PSDFilter" (PSDFilter) "Egis Incorporated" C:\Windows\System32\DRIVERS\psdfilter.sys File exists |||||| "PSDNServ" (PSDNServ) "Egis Incorporated" C:\Windows\System32\DRIVERS\PSDNServ.sys File exists |||||| "PSDVdisk" (psdvdisk) "Egis Incorporated" C:\Windows\System32\DRIVERS\PSDVdisk.sys File exists |||||| "SASDIFSV" (SASDIFSV) "SUPERAdBlocker.com and SUPERAntiSpyware.com" C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS File exists |||||| "SASKUTIL" (SASKUTIL) "SUPERAdBlocker.com and SUPERAntiSpyware.com" C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS File exists |||||| "sptd" (sptd) "Duplex Secure Ltd." C:\Windows\System32\Drivers\sptd.sys File is exclusively opened, access blocked |||||| "ssmdrv" (ssmdrv) "Avira GmbH" C:\Windows\System32\DRIVERS\ssmdrv.sys File exists |||||| "UBHelper" (UBHelper) "NewTech Infosystems Corporation" C:\Windows\system32\drivers\UBHelper.sys File exists |||||| "Upper Class Filter Driver" (NTIDrvr) "NewTech Infosystems, Inc." C:\Windows\System32\DRIVERS\NTIDrvr.sys File exists "vaxscsi" (vaxscsi) C:\Windows\System32\Drivers\vaxscsi.sys File not found |||||| "WSVD" (WSVD) "CyberLink" C:\Windows\system32\drivers\WSVD.sys File exists |||||| "{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}" ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) "Cyberlink Corp." C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl File exists Explorer HKLM\Software\Classes\Folder\shellex\ColumnHandlers |||||| {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" "Adobe Systems, Inc." C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll File exists |||||| {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists HKLM\Software\Classes\Protocols\Filter |||| {B1759355-3EEC-4C1E-B0F1-B719FE26E377} "Google Dictionary Compression filter" "Google Inc." C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll File exists HKLM\Software\Classes\Protocols\Handler |||| {828030A1-22C1-4009-854F-8E305202313F} "livecall" "Microsoft Corporation" C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL File exists |||||| {0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" "Microsoft Corporation" c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll File exists |||| {828030A1-22C1-4009-854F-8E305202313F} "msnim" "Microsoft Corporation" C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL File exists |||||| {03C514A3-1EFB-4856-9F99-10D7BE1653C0} "Windows Live Mail HTML Asynchronous Pluggable Protocol Handler" "Microsoft Corporation" C:\Program Files\Windows Live\Mail\mailcomm.dll File exists HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {AEB6717E-7E19-11d0-97EE-00C04FD91972} "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" File not found | COM-object registry key not found HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved {911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" File not found | COM-object registry key not found {1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" File not found | COM-object registry key not found {34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" File not found | COM-object registry key not found |||||| {0563DB41-F538-4B37-A92D-4659049B7766} "CLSID_WLMCMimeFilter" "Microsoft Corporation" C:\Program Files\Windows Live\Mail\mailcomm.dll File exists {0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" File not found | COM-object registry key not found |||||| {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} "DragDropProtect Class" "Egis Inc." C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll File exists {2b45bd21-71f8-4c8c-a87a-7eeb25a1a3e0} "EPM-PO Shell Extensions" epm-po.dll File not found {2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" File not found | COM-object registry key not found |||||| {8F9D8FBE-C5C1-4B65-986E-51235C9283E8} "FPLaunchCache" "Arachnoid Biometrics Identification Group Corp." C:\Program Files\Acer\Acer Bio Protection\FPLaunchCache.dll File exists |||||| {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" "Apple Inc." C:\Program Files\iTunes\iTunesMiniPlayer.dll File exists {00020d75-0000-0000-c000-000000000046} "lnkfile" File not found | COM-object registry key not found |||||| {FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} "Meine freigegebenen Ordner" "Microsoft Corporation" C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll File exists |||||| {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists |||||| {087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists |||||| {63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists |||||| {3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll File exists {C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" File not found | COM-object registry key not found {E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" File not found | COM-object registry key not found |||||| {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\shlext.dll File exists {1C311AAA-D8B1-4A0A-BEE5-2387FEC583DA} "ShellPlusContextMenu" File not found | COM-object registry key not found {da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" File not found | COM-object registry key not found |||||| {B41DB860-8EE4-11D2-9906-E49FADC173CA} "WinRAR" C:\Program Files\WinRAR\rarext.dll File found, but it contains no detailed information Internet Explorer HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser |||| "Google Toolbar" "Google Inc." C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll File exists "ITBar7Layout" File not found | COM-object registry key not found |||| "Toolbar fuer eBay" C:\Users\Arthur\AppData\Roaming\Toolbars\Toolbar fuer eBay\ebay.dll File exists |||| "Winamp Toolbar" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks |||| {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} "Winamp Search Class" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists || {40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" "Conduit Ltd." C:\Program Files\Winload\tbWinl.dll File exists HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units |||| {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_20" hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2iexp.dll File exists |||| {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2iexp.dll File exists |||| {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_20" hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\npjpi160_20.dll File exists HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions |||||| "Quick-Launching Area" C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe File exists HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar |||||| "Acer eDataSecurity Management" "Egis Incorporated." C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll File exists |||| "Google Toolbar" "Google Inc." C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll File exists |||| "Toolbar fuer eBay" C:\Users\Arthur\AppData\Roaming\Toolbars\Toolbar fuer eBay\ebay.dll File exists |||| {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} "Winamp Toolbar" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists || {40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" "Conduit Ltd." C:\Program Files\Winload\tbWinl.dll File exists HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects |||||| {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} "Adobe PDF Reader Link Helper" "Adobe Systems Incorporated" C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll File exists |||| {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} "Google Dictionary Compression sdch" "Google Inc." C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll File exists |||| {AA58ED58-01DD-4d91-8333-CF10577473F7} "Google Toolbar Helper" "Google Inc." C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll File exists |||| {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} "Google Toolbar Notifier BHO" "Google Inc." C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll File exists |||| {DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" "Sun Microsystems, Inc." C:\Program Files\Java\jre6\bin\jp2ssv.dll File exists |||||| {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} "ShowBarObj Class" "Egis" C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll File exists |||| {AA61DE26-FA67-4575-9033-918671094293} "TBSB03968 Class" C:\Users\Arthur\AppData\Roaming\Toolbars\Toolbar fuer eBay\ebay.dll File exists |||| {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} "Winamp Toolbar Loader" "AOL LLC." C:\Program Files\Winamp Toolbar\winamptb.dll File exists || {40c3cc16-7269-4b32-9531-17f2950fb06f} "Winload Toolbar" "Conduit Ltd." C:\Program Files\Winload\tbWinl.dll File exists {02478D38-C3F9-4efb-9B51-7695ECA05670} "{02478D38-C3F9-4efb-9B51-7695ECA05670}" File not found | COM-object registry key not found {7E853D72-626A-48EC-A868-BA8D5E23E045} "{7E853D72-626A-48EC-A868-BA8D5E23E045}" File not found | COM-object registry key not found Logon %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup |||||| "desktop.ini" C:\Users\Arthur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini File exists %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup |||||| "desktop.ini" C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini File exists HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |||| "AlcoholAutomount" "Alcohol Soft Development Team" "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount File exists |||| "Orb" "Orb Networks" "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background File exists |||||| "SUPERAntiSpyware" "SUPERAntiSpyware.com" C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe File exists |||| "swg" "Google Inc." "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" File exists HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd "StartupPrograms" rdpclip File not found HKLM\Software\Microsoft\Windows\CurrentVersion\Run |||| "Adobe Reader Speed Launcher" "Adobe Systems Incorporated" "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" File exists |||| "ArcadeDeluxeAgent" "CyberLink Corp." "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" File exists |||||| "avgnt" "Avira GmbH" "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min File exists |||||| "BkupTray" "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" File exists |||| "CLMLServer" "CyberLink" "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" File exists |||| "DAEMON Tools" "DT Soft Ltd." "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 File exists || "DivXUpdate" "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW File exists |||| "eAudio" "Acer Incorporated" "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe" File exists |||||| "eDataSecurity Loader" "Egis Incorporated" C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe File exists |||||| "ePower_DMC" "Acer Inc." C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe File exists |||| "Google Desktop Search" "Google" "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup File exists |||| "HostManager" "America Online, Inc." C:\Program Files\Common Files\AOL\1223197373\ee\AOLSoftware.exe File exists |||| "IAAnotif" "Intel Corporation" C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe File exists |||| "iTunesHelper" "Apple Inc." "C:\Program Files\iTunes\iTunesHelper.exe" File exists |||| "LexwareInfoService" "Lexware GmbH & Co. KG" C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe /autostart File exists |||| "LManager" "Dritek System Inc." C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE File exists |||||| "Malwarebytes Anti-Malware (reboot)" "Malwarebytes Corporation" "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript File exists |||| "PlayMovie" "Acer Corp." "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" File exists || "PLFSetI" C:\Windows\PLFSetI.exe File exists |||| "QuickTime Task" "Apple Inc." "C:\Program Files\QuickTime\QTTask.exe" -atboottime File exists |||| "SunJavaUpdateSched" "Sun Microsystems, Inc." "C:\Program Files\Common Files\Java\Java Update\jusched.exe" File exists |||| "WarReg_PopUp" "Acer Incorporated" C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe File exists |||| "WinampAgent" "C:\Program Files\Winamp\winampa.exe" File found, but it contains no detailed information |||| "ZPdtWzdVitaKey MC3000" "Arachnoid Biometrics Identification Group Corp." "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show File exists Print Monitors HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors |||||| "PDFCreator" C:\Windows\system32\pdfcmnnt.dll File found, but it contains no detailed information Services HKLM\SYSTEM\CurrentControlSet\Services |||||| "AOL Connectivity Service" (AOL ACS) "AOL LLC" C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe File exists |||||| "Apple Mobile Device" (Apple Mobile Device) "Apple Inc." C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe File exists |||||| "Avira AntiVir Guard" (AntiVirService) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\avguard.exe File exists |||||| "Avira AntiVir Planer" (AntiVirSchedulerService) "Avira GmbH" C:\Program Files\Avira\AntiVir Desktop\sched.exe File exists |||||| "CLHNService" (CLHNService) C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe File exists |||||| "Cyberlink RichVideo Service(CRVS)" (RichVideo) C:\Program Files\Cyberlink\Shared files\RichVideo.exe File exists |||||| "Dienst "Bonjour"" (Bonjour Service) "Apple Inc." C:\Program Files\Bonjour\mDNSResponder.exe File exists |||||| "eDataSecurity Service" (eDataSecurity Service) "Egis Incorporated" C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe File exists |||||| "Empowering Technology Service" (ETService) C:\Program Files\Acer\Empowering Technology\Service\ETService.exe File exists |||||| "FLEXnet Licensing Service" (FLEXnet Licensing Service) "Macrovision Europe Ltd." C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe File exists |||| "Google Desktop Manager 5.9.911.3589" (GoogleDesktopManager-110309-193829) "Google" C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe File exists |||| "Google Software Updater" (gusvc) "Google" C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe File exists |||||| "iGroupTec Service" (IGBASVC) C:\Program Files\Acer\Acer Bio Protection\BASVC.exe File found, but it contains no detailed information |||| "InstallDriver Table Manager" (IDriverT) "Macrovision Corporation" C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe File exists |||||| "Intel(R) Matrix Storage Event Monitor" (IAANTMON) "Intel Corporation" C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe File exists |||||| "iPod-Dienst" (iPod Service) "Apple Inc." C:\Program Files\iPod\bin\iPodService.exe File exists |||||| "LightScribeService Direct Disc Labeling Service" (LightScribeService) "Hewlett-Packard Company" C:\Program Files\Common Files\LightScribe\LSSrvc.exe File exists |||||| "MobilityService" (MobilityService) C:\Acer\Mobility Center\MobilityService.exe File exists |||||| "NMSAccessU" (NMSAccessU) C:\Program Files\CDBurnerXP\NMSAccessU.exe File found, but it contains no detailed information |||||| "NTI Backup Now 5 Agent Service" (BUNAgentSvc) "NewTech Infosystems, Inc." C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe File exists |||||| "NTI Backup Now 5 Backup Service" (NTIBackupSvc) "NewTech InfoSystems, Inc." C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe File exists |||||| "NTI Backup Now 5 Scheduler Service" (NTISchedulerSvc) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe File found, but it contains no detailed information |||||| "Raw Socket Service" (RS_Service) "Acer Incorporated" C:\Program Files\Acer\Acer VCM\RS_Service.exe File exists || "Sony Ericsson OMSI download service" (OMSI download service) C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe File found, but it contains no detailed information |||||| "StarWind AE Service" (StarWindServiceAE) "Rocket Division Software" C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe File exists Winlogon HKCU\Control Panel\Desktop "SCRNSAVE.EXE" C:\Windows\System32\acer.scr File found, but it contains no detailed information HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify |||||| "AWinNotifyVitaKey MC3000" "Arachnoid Biometrics Identification Group Corp." C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll File exists |||||| "spba" "UPEK Inc." C:\Program Files\Common Files\SPBA\homefus2.dll File exists Winsock Providers HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries |||||| "mdnsNSP" "Apple Inc." C:\Program Files\Bonjour\mdnsNSP.dll File exists If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru und MBR check HTML-Code: MBRCheck, version 1.2.3 |
Lösche bitte die vorhandenen MBRCheck.txt. Starte bitte MBRCheck.exe erneut. Diesmal tippe in das Fenster folgendes ein und bestätige jede Eingabe mit Enter bei
http://img831.imageshack.us/img831/5659/mbr.jpg
Nun findest Du 2 MBRCheck_<Datum>_<Uhrzeit>.txt auf dem Desktop. Poste mir den Inhalt von beiden .txt Dokumenten |
schonmal vielen dank für die antworten... hab alles wie beschrieben gemacht nur dass 3 textdokumente auf dem desktop waren...hier die logs: HTML-Code: MBRCheck, version 1.2.3 HTML-Code: MBRCheck, version 1.2.3 HTML-Code: BRCheck, version 1.2.3 |
Wieso denn jetzt drei Logfiles? Du solltest doch nur den Fix auf Platte0 mit MBR-Code für Vista (Option3) machen :confused: Hast Du Windows neugestartet und zur Kontrolle wie in Posting #8 beschrieben nochmal ausgeführt? |
Hallo, Ich hab es so gemacht wie es beschrieben war. Nachdem ich das Programm ausgeführt hatte waren 2 logfiles (die ersten beiden aus meinem post) und ein weiteres file welches sich nicht öffnen lässt auf dem desktop danach hab ich den Neustart gemacht und dann das prog nochmal ausgeführt, dann war das dritte logfiles zu sehen. Soll ich es nochmal machen? |
Ja nochmal machen. Erst den Fix auf PhysicalDrive0 mit dem MBR-Code für Vista. Dann das gleich nochmal für PhysicalDrive1 |
hallo, habe es noch mal gemacht und jetzt sind 2 logfiles auf dem desktop nr.1 vor dem neustart: HTML-Code: MBRCheck, version 1.2.3 und jetzt das logfile was da war nach dem neustart und erneuten programmstart: HTML-Code: MBRCheck, version 1.2.3 |
hier noch das logfile für das physical drive 1: HTML-Code: MBRCheck, version 1.2.3 |
Zitat:
hast Du eine Vista-DVD zur Hand? Edit: Zitat:
|
hallo, ne vista cd/dvd hab ich nicht, war damals beim laptop nicht dabei, bin gerade dran mir eine zu besorgen gültige lizenz hab ich ja... so weit ich weis ist nur eine festplatte drin mit 3 partitionen Ich bin am überlegen ob ich das ganze system platt mache und komplett neu instaliere oder in den auslieferungzustand zurück setzen lasse, meist du das reicht aus???? Vielen Dank für die Hilfe |
Schau mal hier => Vista Notfall/Recovery-CD 32-Bit - Dr. Windows Lad das iso runter, brenn es per Imagebrennfunktion auf eine CD und starte damit den Rechner (von dieser CD booten). Klick auf Computerreparaturoptionen, weiter, Eingabeaufforderung - die Konsole öffnet sich. Da bitte bootrec.exe /fixboot eintippen (mit enter bestätigen), dann bootrec.exe /fixmbr eintippen (mit enter bestätigen) - Rechner neustarten, CD vorher rausnehmen. Zur Kontrolle MBRCHeck nochmal ausführen und das Log posten. |
hallo, hab fleißig das gemacht was beschrieben wurde, hier das logfile von mbrCheck nach dem neustart: HTML-Code: MBRCheck, version 1.2.3 |
Code: PhysicalDrive0 Model Number: WDCWD3200BEVT-22ZCT0, Rev: 11.01A11 |
Hallo, In den Rechner schauen ist schlecht weile nen Notebook ist da trau ich mich nicht ran. Habe mir mal alles zusammen gesucht an unterlagen da steht dass tatsächlich 2 Festplatten a 320 GB drin sind. Hab gestern nochmal malwarebytes durchlaufen lassen und nichts schlimmes mehr gefunden kann ich den Rechner wieder wie gewohnt nutzen oder ist die Bedrohung immer noch da? Vielen Dank für die hilfe |
Mach das bitte nochmal mit der Recovery-CD. Alles wie gahabt, nur diesen Befehl bitte ausführen: Code: bootrec.exe /fixmbr \device\harddisk1 |
hallo, habe jetzt das system über cd gestartet, dann über eingabeaufforderung bootrec.exe/fixboot (Enter) dann bootrec.exe/fixmbr\device\harddiMBRCheck, version 1.2.3 (c) 2010, AD Command-line: Windows Version: Windows Vista Home Premium Edition Windows Information: Service Pack 1 (build 6001), 32-bit Base Board Manufacturer: Acer, Inc. BIOS Manufacturer: Acer System Manufacturer: Acer, inc. System Product Name: Aspire 6930G Logical Drives Mask: 0x0000007c Kernel Drivers (total 171): 0x8223B000 \SystemRoot\system32\ntkrnlpa.exe 0x82208000 \SystemRoot\system32\hal.dll 0x8040B000 \SystemRoot\system32\kdcom.dll 0x80413000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x80473000 \SystemRoot\system32\PSHED.dll 0x80484000 \SystemRoot\system32\BOOTVID.dll 0x8048C000 \SystemRoot\system32\CLFS.SYS 0x804CD000 \SystemRoot\system32\CI.dll 0x8060E000 \SystemRoot\system32\drivers\Wdf01000.sys 0x8068A000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x80697000 \SystemRoot\System32\Drivers\spsf.sys 0x80797000 \SystemRoot\System32\Drivers\WMILIB.SYS 0x807A0000 \SystemRoot\System32\Drivers\SCSIPORT.SYS 0x805AD000 \SystemRoot\system32\drivers\acpi.sys 0x807C6000 \SystemRoot\system32\drivers\msisadrv.sys 0x807CE000 \SystemRoot\system32\drivers\pci.sys 0x8A20A000 \SystemRoot\System32\drivers\partmgr.sys 0x8A219000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x8A21C000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x8A226000 \SystemRoot\system32\drivers\volmgr.sys 0x8A235000 \SystemRoot\System32\drivers\volmgrx.sys 0x8A27F000 \SystemRoot\System32\drivers\mountmgr.sys 0x8A28F000 \SystemRoot\System32\Drivers\UBHelper.sys 0x8A297000 \SystemRoot\system32\DRIVERS\iaStor.sys 0x8A370000 \SystemRoot\system32\drivers\atapi.sys 0x8A378000 \SystemRoot\system32\drivers\ataport.SYS 0x8A396000 \SystemRoot\system32\drivers\fltmgr.sys 0x8A3C8000 \SystemRoot\system32\drivers\fileinfo.sys 0x8A3D8000 \SystemRoot\system32\DRIVERS\psdfilter.sys 0x8A3E1000 \SystemRoot\system32\Drivers\AlfaFF.sys 0x8A40E000 \SystemRoot\system32\Drivers\ksecdd.sys 0x8A47F000 \SystemRoot\system32\drivers\ndis.sys 0x8A58A000 \SystemRoot\system32\drivers\msrpc.sys 0x8A5B5000 \SystemRoot\system32\drivers\NETIO.SYS 0x8A602000 \SystemRoot\System32\Drivers\Ntfs.sys 0x8A711000 \SystemRoot\system32\drivers\volsnap.sys 0x8A74A000 \SystemRoot\System32\Drivers\spldr.sys 0x8A752000 \SystemRoot\System32\Drivers\mup.sys 0x8A761000 \SystemRoot\System32\drivers\ecache.sys 0x8A788000 \SystemRoot\system32\drivers\disk.sys 0x8A799000 \SystemRoot\system32\drivers\CLASSPNP.SYS 0x8A7BA000 \SystemRoot\system32\drivers\crcdisk.sys 0x8DAE6000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x8DAF1000 \SystemRoot\system32\DRIVERS\tunmp.sys 0x8DAFA000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0x8DAFE000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0x8DC0D000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys 0x8E340000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x8E3DF000 \SystemRoot\System32\drivers\watchdog.sys 0x8E3EC000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x8DB07000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x8DB45000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x8DB54000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x8E607000 \SystemRoot\system32\DRIVERS\NETw5v32.sys 0x8E98E000 \SystemRoot\system32\DRIVERS\winbondcir.sys 0x8E9A3000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x8E9B6000 \SystemRoot\system32\DRIVERS\DKbFltr.sys 0x8E9C0000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x8E9CB000 \SystemRoot\system32\DRIVERS\SynTP.sys 0x8E9FB000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x8DC00000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x8DB66000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x8E3F7000 \SystemRoot\system32\DRIVERS\NTIDrvr.sys 0x8E600000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0x8DB7E000 \SystemRoot\System32\Drivers\a90mbxd7.SYS 0x8DBB4000 \SystemRoot\System32\Drivers\a52k8o9k.SYS 0x8A7D0000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x8EA04000 \SystemRoot\system32\DRIVERS\msiscsi.sys 0x8EA32000 \SystemRoot\system32\DRIVERS\storport.sys 0x8EA73000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x8EA7E000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x8EA95000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x8EAA0000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x8EAC3000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x8EAD2000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x8EAE6000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x8EAFB000 \SystemRoot\system32\DRIVERS\wanatw4.sys 0x8EB01000 \SystemRoot\system32\DRIVERS\termdd.sys 0x8EB11000 \SystemRoot\system32\DRIVERS\seehcri.sys 0x8EB17000 \SystemRoot\system32\DRIVERS\swenum.sys 0x8EB19000 \SystemRoot\system32\DRIVERS\ks.sys 0x8EB43000 \SystemRoot\system32\DRIVERS\circlass.sys 0x8EB51000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x8EB5B000 \SystemRoot\system32\DRIVERS\umbus.sys 0x8EB68000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x8EB9C000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x8EC0C000 \SystemRoot\system32\drivers\RTKVHDA.sys 0x8EE14000 \SystemRoot\system32\drivers\portcls.sys 0x8EE41000 \SystemRoot\system32\drivers\drmk.sys 0x8EE66000 \SystemRoot\system32\DRIVERS\HSXHWAZL.sys 0x8EEA3000 \SystemRoot\system32\DRIVERS\HSX_DPV.sys 0x8F007000 \SystemRoot\system32\DRIVERS\HSX_CNXT.sys 0x8F0BC000 \SystemRoot\system32\drivers\modem.sys 0x8F0C9000 \SystemRoot\system32\drivers\nvhda32v.sys 0x8F0D7000 \SystemRoot\system32\DRIVERS\hidir.sys 0x8F0E2000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0x8F0F2000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x8F0F9000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0x8F102000 \SystemRoot\system32\DRIVERS\mouhid.sys 0x8F10A000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0x8F113000 \SystemRoot\System32\Drivers\Null.SYS 0x8F11A000 \SystemRoot\System32\Drivers\Beep.SYS 0x8F121000 \SystemRoot\System32\drivers\vga.sys 0x8F12D000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x8F14E000 \SystemRoot\system32\drivers\RTSTOR.SYS 0x8F161000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x8F169000 \SystemRoot\system32\drivers\rdpencdd.sys 0x8F171000 \SystemRoot\System32\Drivers\Msfs.SYS 0x8F17C000 \SystemRoot\System32\Drivers\Npfs.SYS 0x8F18A000 \SystemRoot\System32\DRIVERS\rasacd.sys 0x8F808000 \SystemRoot\System32\drivers\tcpip.sys 0x8F8F1000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x8F90C000 \SystemRoot\system32\DRIVERS\tdx.sys 0x8F922000 \SystemRoot\system32\DRIVERS\smb.sys 0x8F936000 \SystemRoot\system32\drivers\afd.sys 0x8F97E000 \SystemRoot\System32\DRIVERS\netbt.sys 0x8F9B0000 \SystemRoot\system32\DRIVERS\pacer.sys 0x8F9C6000 \SystemRoot\system32\DRIVERS\netbios.sys 0x8F9D4000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x8F9E7000 \SystemRoot\system32\DRIVERS\ssmdrv.sys 0x8F193000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 0x8F9ED000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 0x8F1B5000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x8F9F3000 \SystemRoot\system32\drivers\nsiproxy.sys 0x8EFA5000 \SystemRoot\System32\Drivers\dfsc.sys 0x8EFBC000 \SystemRoot\system32\DRIVERS\avipbb.sys 0x8F9FD000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys 0x8F1F1000 \SystemRoot\system32\DRIVERS\hidusb.sys 0x8EFD8000 \SystemRoot\System32\Drivers\tcusb.sys 0x8EFE3000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0x8EBAD000 \SystemRoot\System32\Drivers\usbvideo.sys 0x8EBCE000 \SystemRoot\system32\DRIVERS\cdfs.sys 0x8EBE4000 \SystemRoot\System32\Drivers\crashdmp.sys 0x8DA00000 \SystemRoot\System32\Drivers\dump_iaStor.sys 0x99230000 \SystemRoot\System32\win32k.sys 0x8EC00000 \SystemRoot\System32\drivers\Dxapi.sys 0x8EBF1000 \SystemRoot\system32\DRIVERS\monitor.sys 0x99450000 \SystemRoot\System32\TSDDD.dll 0x8A7DF000 \SystemRoot\system32\drivers\luafv.sys 0x8A3EA000 \SystemRoot\system32\DRIVERS\avgntflt.sys 0x99470000 \SystemRoot\System32\cdd.dll 0x9D00F000 \SystemRoot\system32\drivers\spsys.sys 0x9D0BE000 \SystemRoot\system32\DRIVERS\ipfltdrv.sys 0x9D0D0000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x9D0E0000 \SystemRoot\system32\DRIVERS\nwifi.sys 0x9D10A000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0x9D114000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x9D127000 \SystemRoot\system32\drivers\HTTP.sys 0x9D194000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x9D1B1000 \SystemRoot\system32\DRIVERS\bowser.sys 0x9D1CA000 \SystemRoot\System32\drivers\mpsdrv.sys 0x9D1DF000 \SystemRoot\system32\drivers\mrxdav.sys 0x9EC0B000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x9EC2A000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x9EC63000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x9EC7B000 \SystemRoot\System32\DRIVERS\srv2.sys 0x9ECA2000 \SystemRoot\System32\DRIVERS\srv.sys 0x9ECF0000 \SystemRoot\system32\DRIVERS\atksgt.sys 0x9ED33000 \??\C:\Windows\system32\drivers\int15.sys 0x9ED44000 \SystemRoot\system32\DRIVERS\lirsgt.sys 0x9ED49000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys 0x9ED4D000 \??\C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys 0xA2C02000 \SystemRoot\system32\drivers\peauth.sys 0xA2CE0000 \SystemRoot\system32\DRIVERS\PSDNServ.sys 0xA2CE9000 \SystemRoot\system32\DRIVERS\PSDVdisk.sys 0xA2CFB000 \SystemRoot\System32\Drivers\secdrv.SYS 0xA2D05000 \SystemRoot\System32\drivers\tcpipreg.sys 0xA2D11000 \SystemRoot\system32\DRIVERS\xaudio.sys 0xA2D19000 \??\C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl 0x770B0000 \Windows\System32\ntdll.dll 0x10000000 \Program Files\Alcohol Soft\Alcohol 120\alcoholx.dll Processes (total 96): 0 System Idle Process 4 System 468 C:\Windows\System32\smss.exe 540 csrss.exe 592 C:\Windows\System32\wininit.exe 604 csrss.exe 636 C:\Windows\System32\services.exe 648 C:\Windows\System32\lsass.exe 656 C:\Windows\System32\lsm.exe 816 C:\Windows\System32\svchost.exe 880 C:\Windows\System32\nvvsvc.exe 908 C:\Windows\System32\svchost.exe 944 C:\Windows\System32\svchost.exe 996 C:\Windows\System32\svchost.exe 1028 C:\Windows\System32\svchost.exe 1060 C:\Windows\System32\svchost.exe 1124 C:\Windows\System32\audiodg.exe 1152 C:\Windows\System32\SLsvc.exe 1188 C:\Windows\System32\svchost.exe 1296 C:\Windows\System32\winlogon.exe 1372 C:\Windows\System32\svchost.exe 1560 C:\Windows\System32\spoolsv.exe 1584 C:\Program Files\Avira\AntiVir Desktop\sched.exe 1596 C:\Windows\System32\svchost.exe 1780 C:\Program Files\Avira\AntiVir Desktop\avguard.exe 1812 C:\Program Files\Common Files\aol\acs\AOLacsd.exe 1828 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 1852 C:\Program Files\Bonjour\mDNSResponder.exe 1872 C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe 1900 C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe 1920 C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe 1964 C:\Program Files\Acer\Empowering Technology\Service\ETService.exe 480 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe 680 C:\Program Files\Acer\Acer Bio Protection\BASVC.exe 1232 C:\Windows\System32\rundll32.exe 588 C:\Program Files\Common Files\SPBA\upeksvr.exe 1660 C:\Program Files\Common Files\LightScribe\LSSrvc.exe 2108 C:\ACER\Mobility Center\MobilityService.exe 2212 C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe 2236 C:\Program Files\CDBurnerXP\NMSAccessU.exe 2252 C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe 2456 C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe 2496 C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe 2564 C:\Windows\System32\svchost.exe 2608 C:\Program Files\Cyberlink\Shared files\RichVideo.exe 2636 C:\Program Files\Acer\Acer VCM\RS_Service.exe 2672 C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe 2704 C:\Windows\System32\svchost.exe 2744 C:\Windows\System32\svchost.exe 2768 C:\Windows\System32\SearchIndexer.exe 2848 C:\Windows\System32\drivers\XAudio.exe 3212 C:\Windows\System32\taskeng.exe 3320 WmiPrvSE.exe 3404 WmiPrvSE.exe 3820 C:\Windows\System32\userinit.exe 3840 C:\Windows\System32\dwm.exe 3872 C:\Windows\System32\taskeng.exe 3964 C:\Windows\explorer.exe 4036 C:\Program Files\Windows Defender\MSASCui.exe 4056 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe 4068 C:\Windows\RtHDVCpl.exe 2056 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 2104 C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe 2192 C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe 2200 C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe 2232 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe 2756 C:\Windows\System32\rundll32.exe 2884 C:\Windows\PLFSetI.exe 3384 C:\Program Files\Launch Manager\QtZgAcer.EXE 3460 C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe 992 C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe 1236 C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe 3076 C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe 1680 C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe 1168 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe 1368 C:\Program Files\Winamp\winampa.exe 1984 C:\Program Files\DAEMON Tools\daemon.exe 1576 C:\Program Files\Common Files\aol\1223197373\ee\aolsoftware.exe 3048 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe 2008 C:\Program Files\Common Files\Java\Java Update\jusched.exe 2912 C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe 2404 C:\Program Files\DivX\DivX Update\DivXUpdate.exe 3436 C:\Program Files\iTunes\iTunesHelper.exe 3432 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 3096 C:\Program Files\Alcohol Soft\Alcohol 120\AxCmd.exe 3072 C:\Program Files\Windows Media Player\wmpnscfg.exe 3064 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe 488 C:\Windows\System32\PresentationSettings.exe 2072 C:\Windows\System32\wbem\unsecapp.exe 2556 C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe 4308 C:\Users\Arthur\AppData\Local\temp\RtkBtMnt.exe 4368 C:\Program Files\Windows Media Player\wmpnetwk.exe 4648 dllhost.exe 4700 dllhost.exe 4764 C:\Users\Arthur\Desktop\MBRCheck.exe 4780 C:\Windows\System32\conime.exe \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`80100000 (NTFS) \\.\D: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS) \\.\E: --> \\.\PhysicalDrive0 at offset 0x00000026`82e00000 (NTFS) PhysicalDrive0 Model Number: WDCWD3200BEVT-22ZCT0, Rev: 11.01A11 PhysicalDrive1 Model Number: WDCWD3200BEVT-22ZCT0, Rev: 11.01A11 Size Device Name MBR Status -------------------------------------------- 298 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979 298 GB \\.\PhysicalDrive1 Unknown MBR code SHA1: B8E2175818464D3FFEB1C1B647995AD0F49BFDB5 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: dann neustart und mbrchek....hier das logfile: |
hallo, kann ich jetzt wieder problemlos surfen oder lieber doch das system neu installieren??? kann man den pc auf seine werkseinstellungen zurück setzen ohne die vista recovery cd???? |
Oh, hab Deinen Strang übersehen. Mach bitte nochmal ein Code: bootrec.exe /fixboot \device\harddisk1 |
hallo, hab alles wie beschrieben ausgeführt, hier das logfile vom mbr-check: PHP-Code: |
Zitat:
Ich lass es jetzt einfach mal so, da Du ja in der Wiederherstellungskonsole bootrec /fixmbr auf \Device\HardDisk1 losgelassen hast... Und Deine Bootplatte ist die erste physikalische Platte, also Harddisk0 und da ist der MBR ja ok. Sach mir Bescheid falls Du den MBR wirklich zurückgesetzt haben willst, dann probieren wir das nochmal mit dem dd-Befehl unter Linux :snyper: Mach bitte erstmal zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs. Denk dran beide Tools zu updaten vor dem Scan!! |
hi, hier die komplettscans: HTML-Code: Malwarebytes' Anti-Malware 1.46 HTML-Code: SUPERAntiSpyware Scan Log |
Zitat:
|
Alle Zeitangaben in WEZ +1. Es ist jetzt 08:38 Uhr. |
Copyright ©2000-2025, Trojaner-Board